GHSA-v3f6-m9j2-437p: Medium severity nuget/Microsoft.AspNetCore.Server.IISIntegration vulnerability
Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-8cp2-47hg-mfgh. This link is maintained to preserve external references.
Original Description Improper handling of highly compressed data (data amplification) in ASP.NET Core allows an unauthorized attacker to deny service over a network.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
nuget/Microsoft.AspNetCore.Server.IISIntegrationto a version that resolves this vulnerability.Fixed in 10.0.12 - Upgrade
Upgrade
nuget/Microsoft.AspNetCore.Server.IISIntegrationto a version that resolves this vulnerability.Fixed in 9.0.20 - Upgrade
Upgrade
nuget/Microsoft.AspNetCore.Server.IISIntegrationto a version that resolves this vulnerability.Fixed in 8.0.31 - Upgrade
Upgrade
nuget/Microsoft.AspNetCore.Server.IISIntegrationto a version that resolves this vulnerability.Fixed in 11.0.0-rc.1
Event History
Frequently Asked Questions
Should this advisory be tracked as a separate vulnerability?
No. It has been withdrawn as a duplicate of GHSA-8cp2-47hg-mfgh and is retained only to preserve external references. Use the duplicate advisory for remediation and impact tracking.
What capability does an attacker need to exploit the issue?
The supplied vector indicates network access is required, with no privileges or user interaction required. Exploitation is rated high complexity and involves sending highly compressed data that is improperly handled.
What is the likely impact of successful exploitation?
Successful exploitation can cause a denial of service through data amplification. The provided severity vector indicates availability impact only, with no stated confidentiality or integrity impact.